IT Compliance Officer (DORA / AI Act / NIST / IT Governance)
Engineer.BG · Sofia, Sofia City, Bulgaria · Mid
Умения
Сертификати
Описание
Описание на позицията
We are looking for an experienced IT Compliance Officer to support and strengthen our regulatory compliance, ICT governance, cybersecurity, and operational resilience framework. The role focuses on implementation and maintenance of controls related to Digital Operational Resilience Act (DORA), EU Artificial Intelligence Act, NIST Cybersecurity Framework, and internal IT governance standards.
The successful candidate will work closely with IT, Information Security, Risk Management, Legal, Compliance, and business teams to ensure alignment with regulatory requirements, AI governance obligations, security standards, and operational resilience objectives.
Key Responsibilities
- Support the implementation and ongoing maintenance of compliance requirements related to:
- Digital Operational Resilience Act (DORA)
- EU Artificial Intelligence Act
- NIST Cybersecurity Framework
- Maintain and improve IT governance, ICT risk management, AI governance, and operational resilience processes
- Develop, review, and update IT, cybersecurity, and AI governance policies and procedures
- Maintain ICT and compliance registers, including:
- ICT asset register
- vulnerability register
- incident register
- third-party ICT provider register
- AI systems inventory and risk classification register
- Support AI governance activities, including:
- AI system classification
- AI risk assessments
- documentation and transparency requirements
- monitoring of AI-related controls
- Perform gap assessments against DORA, AI Act, NIST, ISO 27001, and internal standards
- Coordinate remediation activities related to audit findings and compliance gaps
- Participate in ICT risk assessments and control testing activities
- Support internal, external, and regulatory audits
- Monitor compliance status and prepare reports, metrics, and management dashboards
- Collaborate with infrastructure, cloud, security, and development teams to ensure implementation of required controls
- Support business continuity, disaster recovery, and third-party ICT risk management initiatives
Required Qualifications
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Law & Technology, or related field
- 2+ years of experience in IT compliance, cybersecurity governance, ICT risk management, or regulatory compliance
- Good understanding of:
- Digital Operational Resilience Act (DORA)
- EU Artificial Intelligence Act
- NIST Cybersecurity Framework
- ISO/IEC 27001
- IT governance and risk management frameworks
- Understanding of AI governance principles and AI lifecycle management
- Experience with IT policies, procedures, and audit activities
- Knowledge of vulnerability management, asset management, and incident management processes
- Strong analytical, organizational, and communication skills
- Professional working proficiency in English
Preferred Qualifications
- Experience in financial services, fintech, AI governance, or regulated environments
- Familiarity with cloud security, AI risk management, and third-party ICT oversight
- Experience with governance and compliance tools such as:
- ServiceNow
- Jira
- GRC platforms
- Relevant certifications are considered an advantage:
- ISO 27001
- CISA
- CRISC
- Security+
- AI governance or AI ethics certifications
What We Offer
- Opportunity to work on strategic regulatory, cybersecurity, and AI governance initiatives
- International and collaborative working environment
- Professional development and certification support
- Hybrid working model
- Competitive compensation package, additional benefits
Location
Sofia, Bulgaria / Hybrid
Employment Type
Full-time
Apply
Please send your CV and a short motivation letter to the recruitment team.
История на обявата
- 15 август 2026 г.Появи сеобхождане
- 19 август 2026 г.Затворенаобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Mid според бенчмарка на CSF.BG — не е предложение на работодателя.
Само 2 обяви за тази роля и ниво публикуват заплата — твърде малко за средна стойност.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.